Current legal status
The DPDP Act, 2023 and DPDP Rules, 2025 have phased commencement dates. As of this statement’s effective date, several institutional provisions are in force, section 6(9) and section 27(1)(d) are scheduled one year after the 13 November 2025 notification, and most operational obligations and rights are scheduled eighteen months after it.
Whats91 is preparing for the framework while following other applicable Indian privacy, technology, contract, and consumer requirements. This page is not a certification and does not claim every DPDP obligation is already in force.
Roles
Whats91 expects to act as a Data Fiduciary for information it controls about website visitors, administrators, prospects, and billing or support contacts. For customer-controlled contact and messaging data, Whats91 generally acts on the customer’s instructions as a processor or service provider.
Whats91 does not claim Significant Data Fiduciary status. That status applies only if the Central Government notifies Whats91 or a class that includes it.
Notices, consent, and permitted uses
Readiness work includes clear notices, itemised data descriptions, specified purposes, and straightforward consent withdrawal where consent is used. Other processing will be assessed against uses permitted by applicable law rather than imported legal bases not provided by the DPDP Act.
Data Principal rights
When the relevant provisions apply, the framework provides rights to access processing information, correction and erasure, grievance redressal, and nomination. Consent withdrawal is supported where consent is the basis.
Data portability is not presented as a DPDP statutory right. It may still be offered contractually or required by another law or platform term.
Security readiness
The readiness program considers access control, logging, monitoring, backups, incident handling, secure vendor arrangements, and protections appropriate to the data and service. Cipher, certification, penetration-test, or universal MFA claims will be published only after scope and evidence are verified.
Personal data breach readiness
The notified Rules contemplate notice to affected Data Principals and an initial intimation to the Board without delay, followed by specified details to the Board within seventy-two hours unless a longer period is allowed. Whats91 is aligning its response process to requirements applicable at the time of an incident.
Retention and erasure
Retention will be tied to specified purposes, customer instructions, security and audit needs, and legal records. We do not promise universal deletion within thirty days where backups, fraud prevention, disputes, platform records, or law require a different period.
Children’s data
Whats91 is intended for business users. Where relevant DPDP provisions apply, processing a child’s data requires the safeguards and parental consent required by law unless an exemption exists. Customers are responsible for age-appropriate messaging programmes.
Processing outside India
The DPDP framework allows transfers subject to restrictions or requirements specified by the Central Government. This statement does not claim a general India-only storage requirement or present GDPR Standard Contractual Clauses as a standalone DPDP requirement.
Questions and grievances
Until a formally appointed DPO or different grievance contact is confirmed, send privacy questions to support@whats91.com with the subject “Privacy request”. Whats91 will verify the requester and respond within the period required by applicable law.
Readiness updates
This statement will be updated as provisions commence and Whats91 verifies controls, contacts, retention schedules, and service-provider records.
Referenced laws and platform policies
Contact Whats91
For questions, account notices, privacy requests, or legal correspondence, contact us directly. Include enough context to route the request, but do not send passwords, API keys, or one-time codes.